Store-Now-Decrypt-Later: why your communications today are already at risk
There is a cyber threat that requires no direct attack, leaves no traces in logs, and triggers no alarms. It is called "store-now-decrypt-later" (SNDL) and it is already happening. Intelligence agencies, APT groups, and state actors are intercepting and archiving vast amounts of encrypted traffic, with the goal of decrypting it in the future when quantum computers become operational.
How the SNDL attack works
- 1.A malicious actor intercepts encrypted traffic on WAN networks (inter-site communications, telemetry, SCADA data).
- 2.The data is archived, waiting for quantum computers to become powerful enough.
- 3.When the computational capacity becomes available, algorithms like Shor's will be able to break RSA, ECC, and Diffie-Hellman in hours.
- 4.All archived data — contracts, strategic communications, trade secrets — will become readable.
This is not science fiction
The NSA, UK NCSC, and German BSI have publicly confirmed that the SNDL threat is real and current. NIST finalized post-quantum standards (FIPS 203, ML-KEM) in August 2024 precisely to address this urgency. The estimated timeline for a cryptographically relevant quantum computer ranges between 5 and 15 years — but data intercepted today will still have strategic value in 10, 20, or 30 years.
If your communications contain information that will still be sensitive in 10 years — contracts, intellectual property, personal data, strategies — the SNDL attack already concerns you today.
The solution: post-quantum cryptography
Migration to post-quantum algorithms such as ML-KEM (FIPS 203) is the only effective countermeasure against SNDL. These algorithms are based on mathematical problems (structured lattices) that remain computationally intractable even for quantum computers.
AEGIDA Framework implements ML-KEM for key exchange, combined with AES-256-GCM for symmetric encryption and a stealth layer that makes traffic indistinguishable from normal HTTPS. This three-layer approach protects against both future quantum attacks and traffic interception and analysis techniques already available today.
What to do now
The transition to post-quantum cryptography is not a future project: it is a present urgency. Every day of delay is another day of potentially intercepted and archived data. Organizations managing critical infrastructure, health data, financial information, or trade secrets should begin PQC migration immediately.